QuestionQ1057

Technology and Security

An organization has been alerted that a disgruntled, terminated IT administrator has attempted to gain access to the corporate network. Which of the following findings should be of GREATEST concern to the organization?

  • A A brute force attack has been detected
  • B An external vulnerability scan has been detected
  • C An increase in support requests has been observed
  • D Authentication logs have been disabled
Explanation

Disabled authentication logs eliminate a critical audit trail for detecting and investigating unauthorized access. A terminated administrator may know privileged access paths, so loss of authentication logging can conceal a successful compromise and impede incident response.

Community Discussion

No comments yet. Be the first to start the discussion!